<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Dotdeb &#187; PHP</title>
	<atom:link href="http://www.dotdeb.org/tag/php/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.dotdeb.org</link>
	<description>The repository for Debian-based LAMP servers</description>
	<lastBuildDate>Mon, 06 Sep 2010 15:52:23 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>PHP 5.2.14 is available too</title>
		<link>http://www.dotdeb.org/2010/07/25/php-5-2-14-is-available-too/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=php-5-2-14-is-available-too</link>
		<comments>http://www.dotdeb.org/2010/07/25/php-5-2-14-is-available-too/#comments</comments>
		<pubDate>Sun, 25 Jul 2010 13:11:24 +0000</pubDate>
		<dc:creator>Guillaume Plessis</dc:creator>
				<category><![CDATA[PHP]]></category>
		<category><![CDATA[PHP5]]></category>
		<category><![CDATA[release]]></category>

		<guid isPermaLink="false">http://www.dotdeb.org/?p=388</guid>
		<description><![CDATA[On july, 22nd, the PHP Group released PHP 5.2.14 :
The [...]]]></description>
			<content:encoded><![CDATA[<p>On july, 22nd, the PHP Group released PHP 5.2.14 :</p>
<blockquote><p>The PHP development team would like to announce the immediate availability of PHP 5.2.14. This release focuses on improving the stability of the PHP 5.2.x branch with over 60 bug fixes, some of which are security related.</p>
<p>This release marks the end of the active support for PHP 5.2. Following this release the PHP 5.2 series will receive no further active bug maintenance. Security fixes for PHP 5.2 might be published on a case by cases basis. All users of PHP 5.2 are encouraged to upgrade to PHP 5.3.</p></blockquote>
<p>The packages for Debian &#8220;Lenny&#8221; are now available on Dotdeb.</p>
<p>Of course, you&#8217;re advised to read the full <a title="PHP 5.2.14 full announcement" href="http://www.php.net/archive/2010.php#id2010-07-22-1">announcement</a> and the <a title="the PHP5 Changelog" href="http://www.php.net/ChangeLog-5.php#5.2.14">Changelog</a> before upgrading.</p>
<p>Thanks (again) to Stefan Esser and the <a title="The month of PHP security" href="http://php-security.org/">Month of PHP security</a> for improving PHP.</p>
 <p>Feel free to Flattr this post at <a href="http://flattr.com/" title="Flattr" target="_blank">flattr.com</a>, if you like it.</p> <p><a href="http://flattr.com/" title="Flattr" target="_blank"><img src="http://www.dotdeb.org/wp-content/plugins/flattrss/button-compact-static-100x17.png" alt="flattr this!"/></a></p><div style="float: right; margin-left: 10px;"><a href="http://twitter.com/share?url=http://www.dotdeb.org/2010/07/25/php-5-2-14-is-available-too/&via=dotdeb&text=PHP 5.2.14 is available too&related=w_a_s_t_e:Dotdeb's maintainer&lang=en&count=horizontal" class="twitter-share-button">Tweet</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script></div><div style="float: right; margin-left: 10px;"><a href="http://twitter.com/share?url=http://www.dotdeb.org/2010/07/25/php-5-2-14-is-available-too/&via=dotdeb&text=PHP 5.2.14 is available too&related=w_a_s_t_e:Dotdeb's maintainer&lang=en&count=horizontal" class="twitter-share-button">Tweet</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script></div>]]></content:encoded>
			<wfw:commentRss>http://www.dotdeb.org/2010/07/25/php-5-2-14-is-available-too/feed/</wfw:commentRss>
		<slash:comments>14</slash:comments>
		</item>
		<item>
		<title>PHP 5.3.3 packages are available</title>
		<link>http://www.dotdeb.org/2010/07/25/php-5-3-3-packages-are-available/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=php-5-3-3-packages-are-available</link>
		<comments>http://www.dotdeb.org/2010/07/25/php-5-3-3-packages-are-available/#comments</comments>
		<pubDate>Sun, 25 Jul 2010 11:03:09 +0000</pubDate>
		<dc:creator>Guillaume Plessis</dc:creator>
				<category><![CDATA[PHP]]></category>
		<category><![CDATA[PHP5]]></category>
		<category><![CDATA[release]]></category>

		<guid isPermaLink="false">http://www.dotdeb.org/?p=384</guid>
		<description><![CDATA[On july, 22nd, the PHP Group released PHP 5.3.3 :
The  [...]]]></description>
			<content:encoded><![CDATA[<p>On july, 22nd, the PHP Group released PHP 5.3.3 :</p>
<blockquote><p>The PHP development team would like to announce the immediate availability of PHP 5.3.3. This release focuses on improving the stability and security of the PHP 5.3.x branch with over 100 bug fixes, some of which are security related. All users are encouraged to upgrade to this release.</p></blockquote>
<p>The packages for Debian &#8220;Lenny&#8221; are now available on Dotdeb on <a title="PHP 5.3 Dotdeb repository" href="http://php53.dotdeb.org/">the usual repository</a>.</p>
<p>Of course, you should read the full <a title="PHP 5.3.3 full announcement" href="http://www.php.net/archive/2010.php#id2010-07-22-2">announcement</a>, <a title="the PHP 5.3 migration guide" href="http://www.php.net/migration53">the PHP 5.3 migration guide</a> and consult the <a title="the PHP5 Changelog" href="http://www.php.net/ChangeLog-5.php#5.3.3">Changelog</a>.</p>
<p><strong>Caution :</strong> (to PHP-FPM users) with the inclusion of PHP-FPM in the PHP 5.3 core, the syntax of the configuration file (<tt>/etc/php5/fpm/php5-fpm.conf</tt>) has changed. It switched from a XML syntax to an INI one. Please prepare your new configuration file before upgrading, by reading carefully <a href="http://www.php.net/manual/en/install.fpm.configuration.php">the PHP documentation</a> and <a title="PHP-FPM ini syntax RFC" href="http://wiki.php.net/rfc/fpm/ini_syntax">this page</a>.</p>
<p>And thanks to Stefan Esser and the <a title="The month of PHP security" href="http://php-security.org/">Month of PHP security</a> for improving PHP.</p>
<script type="text/javascript">
var flattr_wp_ver = '0.9.14';
var flattr_uid = '13101';
var flattr_url = 'http://www.dotdeb.org';
var flattr_lng = 'en_GB';
var flattr_cat = 'text';
var flattr_tag = 'blog,wordpress,rss,feed';
var flattr_btn = 'large';
var flattr_tle = 'Dotdeb';
var flattr_dsc = 'The repository for Debian-based LAMP servers';
</script>
<script src="https://api.flattr.com/js/0.5.0/load.js?mode=auto" type="text/javascript"></script> <p>Feel free to Flattr this post at <a href="http://flattr.com/" title="Flattr" target="_blank">flattr.com</a>, if you like it.</p> <p><a href="http://flattr.com/" title="Flattr" target="_blank"><img src="http://www.dotdeb.org/wp-content/plugins/flattrss/button-compact-static-100x17.png" alt="flattr this!"/></a></p><div style="float: right; margin-left: 10px;"><a href="http://twitter.com/share?url=http://www.dotdeb.org/2010/07/25/php-5-3-3-packages-are-available/&via=dotdeb&text=PHP 5.3.3 packages are available&related=w_a_s_t_e:Dotdeb's maintainer&lang=en&count=horizontal" class="twitter-share-button">Tweet</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script></div><div style="float: right; margin-left: 10px;"><a href="http://twitter.com/share?url=http://www.dotdeb.org/2010/07/25/php-5-3-3-packages-are-available/&via=dotdeb&text=PHP 5.3.3 packages are available&related=w_a_s_t_e:Dotdeb's maintainer&lang=en&count=horizontal" class="twitter-share-button">Tweet</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script></div>]]></content:encoded>
			<wfw:commentRss>http://www.dotdeb.org/2010/07/25/php-5-3-3-packages-are-available/feed/</wfw:commentRss>
		<slash:comments>46</slash:comments>
		</item>
		<item>
		<title>May is the month of PHP security</title>
		<link>http://www.dotdeb.org/2010/05/04/may-is-the-month-of-php-security/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=may-is-the-month-of-php-security</link>
		<comments>http://www.dotdeb.org/2010/05/04/may-is-the-month-of-php-security/#comments</comments>
		<pubDate>Tue, 04 May 2010 12:26:21 +0000</pubDate>
		<dc:creator>Guillaume Plessis</dc:creator>
				<category><![CDATA[PHP]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.dotdeb.org/?p=349</guid>
		<description><![CDATA[According to Stefan Esser, author of the Suhosin patch, [...]]]></description>
			<content:encoded><![CDATA[<p>According to Stefan Esser, author of the <a title="The Suhosin PHP hardening patch" href="http://www.suhosin.org/">Suhosin</a> patch, May 2010 will be the &#8220;Month of PHP Security&#8221; :</p>
<blockquote><p>This initiative continues the effort of Hardened-PHP&#8217;s Month of PHP Bugs in 2007 to improve the security of PHP and the PHP ecosystem by disclosing vulnerabilities in PHP and PHP applications on the one hand and on the other hand by publishing articles and tools that help PHP application developers to develop more secure PHP applications.</p></blockquote>
<p style="text-align: center;"><a style="text-decoration: none;" href="http://php-security.org/"><img class="aligncenter size-full wp-image-350" title="mopb-logo" src="http://www.dotdeb.org/wp-content/uploads/2010/05/mopb-logo.png" alt="" width="147" height="96" /></a></p>
<p>You&#8217;ll find more information on <a title="the &quot;Month of PHP Security&quot; website" href="http://php-security.org/">the MoPS website</a> and you can follow <a title="&quot;Month of PHP Security&quot; Twitter account" href="http://twitter.com/mops_2010">its twitter account</a> to discover each vulnerability as soon as it&#8217;s reported.</p>
 <p>Feel free to Flattr this post at <a href="http://flattr.com/" title="Flattr" target="_blank">flattr.com</a>, if you like it.</p> <p><a href="http://flattr.com/" title="Flattr" target="_blank"><img src="http://www.dotdeb.org/wp-content/plugins/flattrss/button-compact-static-100x17.png" alt="flattr this!"/></a></p><div style="float: right; margin-left: 10px;"><a href="http://twitter.com/share?url=http://www.dotdeb.org/2010/05/04/may-is-the-month-of-php-security/&via=dotdeb&text=May is the month of PHP security&related=w_a_s_t_e:Dotdeb's maintainer&lang=en&count=horizontal" class="twitter-share-button">Tweet</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script></div><div style="float: right; margin-left: 10px;"><a href="http://twitter.com/share?url=http://www.dotdeb.org/2010/05/04/may-is-the-month-of-php-security/&via=dotdeb&text=May is the month of PHP security&related=w_a_s_t_e:Dotdeb's maintainer&lang=en&count=horizontal" class="twitter-share-button">Tweet</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script></div>]]></content:encoded>
			<wfw:commentRss>http://www.dotdeb.org/2010/05/04/may-is-the-month-of-php-security/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>PHP 5.3.2 and PHP 5.2.13 get an update</title>
		<link>http://www.dotdeb.org/2010/04/21/php-5-3-2-and-php-5-2-13-get-an-update/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=php-5-3-2-and-php-5-2-13-get-an-update</link>
		<comments>http://www.dotdeb.org/2010/04/21/php-5-3-2-and-php-5-2-13-get-an-update/#comments</comments>
		<pubDate>Wed, 21 Apr 2010 09:38:58 +0000</pubDate>
		<dc:creator>Guillaume Plessis</dc:creator>
				<category><![CDATA[PHP]]></category>
		<category><![CDATA[PHP5]]></category>
		<category><![CDATA[release]]></category>

		<guid isPermaLink="false">http://www.dotdeb.org/?p=347</guid>
		<description><![CDATA[New packages of PHP 5.3.1 and PHP 5.2.13 has been uploa [...]]]></description>
			<content:encoded><![CDATA[<p>New packages of PHP 5.3.1 and PHP 5.2.13 has been uploaded to fix some annoying bugs :</p>
<ul>
<li><a href="http://www.php.net/filter_var">filter_var</a> now validates correctly the hostnames that include &#8216;-&#8217; (<a title="Bug #51192	FILTER_VALIDATE_URL will invalidate a hostname that includes '-'" href="http://bugs.php.net/51192">bug #51192</a>)</li>
<li><a title="Image Processing and GD" href="http://www.php.net/manual/en/book.image.php">the GD bundled library</a> has been patched to fix some TrueType issues (<a title="Bug #51207	imageTTFText: misalignment of characters which extend beyond their left margin" href="http://bugs.php.net/51207">bug #51207</a>, &#8230;)</li>
</ul>
<p>In addition, PHP 5.3.2 now restarts softly, without any problem (thanks to Daniel Hahler).</p>
<script type="text/javascript">
var flattr_wp_ver = '0.9.14';
var flattr_uid = '13101';
var flattr_url = 'http://www.dotdeb.org';
var flattr_lng = 'en_GB';
var flattr_cat = 'text';
var flattr_tag = 'blog,wordpress,rss,feed';
var flattr_btn = 'large';
var flattr_tle = 'Dotdeb';
var flattr_dsc = 'The repository for Debian-based LAMP servers';
</script>
<script src="https://api.flattr.com/js/0.5.0/load.js?mode=auto" type="text/javascript"></script> <p>Feel free to Flattr this post at <a href="http://flattr.com/" title="Flattr" target="_blank">flattr.com</a>, if you like it.</p> <p><a href="http://flattr.com/" title="Flattr" target="_blank"><img src="http://www.dotdeb.org/wp-content/plugins/flattrss/button-compact-static-100x17.png" alt="flattr this!"/></a></p><div style="float: right; margin-left: 10px;"><a href="http://twitter.com/share?url=http://www.dotdeb.org/2010/04/21/php-5-3-2-and-php-5-2-13-get-an-update/&via=dotdeb&text=PHP 5.3.2 and PHP 5.2.13 get an update&related=w_a_s_t_e:Dotdeb's maintainer&lang=en&count=horizontal" class="twitter-share-button">Tweet</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script></div><div style="float: right; margin-left: 10px;"><a href="http://twitter.com/share?url=http://www.dotdeb.org/2010/04/21/php-5-3-2-and-php-5-2-13-get-an-update/&via=dotdeb&text=PHP 5.3.2 and PHP 5.2.13 get an update&related=w_a_s_t_e:Dotdeb's maintainer&lang=en&count=horizontal" class="twitter-share-button">Tweet</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script></div>]]></content:encoded>
			<wfw:commentRss>http://www.dotdeb.org/2010/04/21/php-5-3-2-and-php-5-2-13-get-an-update/feed/</wfw:commentRss>
		<slash:comments>64</slash:comments>
		</item>
		<item>
		<title>PHP 5.3.2 is available too!</title>
		<link>http://www.dotdeb.org/2010/03/08/php-5-3-2-is-available-too/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=php-5-3-2-is-available-too</link>
		<comments>http://www.dotdeb.org/2010/03/08/php-5-3-2-is-available-too/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 22:29:56 +0000</pubDate>
		<dc:creator>Guillaume Plessis</dc:creator>
				<category><![CDATA[PHP]]></category>
		<category><![CDATA[PHP5]]></category>
		<category><![CDATA[release]]></category>

		<guid isPermaLink="false">http://www.dotdeb.org/?p=340</guid>
		<description><![CDATA[A few days ago, the PHP Group released PHP 5.3.2. It fi [...]]]></description>
			<content:encoded><![CDATA[<p>A few days ago, the PHP Group released PHP 5.3.2. It fixes severe security issues and some other bugs :</p>
<blockquote><p>The PHP development team is proud to announce the immediate release of PHP 5.3.2. This is a maintenance release in the 5.3 series, which includes a large number of bug fixes.</p>
<p><strong>Security Enhancements and Fixes in PHP 5.3.2:</strong></p>
<ul>
<li>Improved LCG entropy. (Rasmus, Samy Kamkar)</li>
<li>Fixed safe_mode validation inside tempnam() when the directory path does not end with a /). (Martin Jansen)</li>
<li>Fixed a possible open_basedir/safe_mode bypass in the session extension identified by Grzegorz Stachowiak. (Ilia)</li>
</ul>
<p>(&#8230;)</p></blockquote>
<p>It is now available on Dotdeb (still on <a title="PHP 5.3 Dotdeb repository" href="http://php53.dotdeb.org/">a separate repository</a>) with the following changes :</p>
<ul>
<li>id3 and mailparse PECL extensions have been removed from the repository. If some of them were useful to you, please let me know. Don&#8217;t forget that there&#8221;s an easy way to <a title="How to package PECL extensions by yourself" href="http://www.dotdeb.org/2008/09/25/how-to-package-php-extensions-by-yourself/">package PECL extensions by yourself</a></li>
<li><a title="How to package PECL extensions by yourself" href="http://www.dotdeb.org/2008/09/25/how-to-package-php-extensions-by-yourself/"></a>the memcache extension has been downgraded to v3.0.3 because of a <a title="PECL bug #16061" href="http://pecl.php.net/bugs/bug.php?id=16061">bug in the session redundancy</a></li>
<li>php5-fpm is now an alternative dependency og the php5 meta-package</li>
</ul>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-341" title="ElePHPant v3.0" src="http://www.dotdeb.org/wp-content/uploads/2010/03/elephpant_281_193.png" alt="" width="281" height="193" /></p>
<p>As usual, please read <a title="PHP 5.3.2 release announcement" href="http://www.php.net/archive/2010.php#id2010-03-04-1">the release announcement</a> and the full <a title="The PHP5 Changelog" href="http://www.php.net/ChangeLog-5.php#5.3.2">Changelog</a> before upgrading. If you&#8217;re migrating from PHP 5.2, you can also take a look at <a title="from PHP 5.2 to PHP 5.3 migration guide" href="http://www.php.net/migration53">migration guide</a>.</p>
<p><strong>[Update]</strong> The packages have been updated to fix <a title="PHP bug #51242" href="http://bugs.php.net/51242">a MySQL connection issue</a>. The geoip PECL extension is back.</p>
 <p>Feel free to Flattr this post at <a href="http://flattr.com/" title="Flattr" target="_blank">flattr.com</a>, if you like it.</p> <p><a href="http://flattr.com/" title="Flattr" target="_blank"><img src="http://www.dotdeb.org/wp-content/plugins/flattrss/button-compact-static-100x17.png" alt="flattr this!"/></a></p><div style="float: right; margin-left: 10px;"><a href="http://twitter.com/share?url=http://www.dotdeb.org/2010/03/08/php-5-3-2-is-available-too/&via=dotdeb&text=PHP 5.3.2 is available too!&related=w_a_s_t_e:Dotdeb's maintainer&lang=en&count=horizontal" class="twitter-share-button">Tweet</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script></div><div style="float: right; margin-left: 10px;"><a href="http://twitter.com/share?url=http://www.dotdeb.org/2010/03/08/php-5-3-2-is-available-too/&via=dotdeb&text=PHP 5.3.2 is available too!&related=w_a_s_t_e:Dotdeb's maintainer&lang=en&count=horizontal" class="twitter-share-button">Tweet</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script></div>]]></content:encoded>
			<wfw:commentRss>http://www.dotdeb.org/2010/03/08/php-5-3-2-is-available-too/feed/</wfw:commentRss>
		<slash:comments>37</slash:comments>
		</item>
		<item>
		<title>PHP 5.2.13 is available</title>
		<link>http://www.dotdeb.org/2010/03/07/php-5-2-13-is-available/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=php-5-2-13-is-available</link>
		<comments>http://www.dotdeb.org/2010/03/07/php-5-2-13-is-available/#comments</comments>
		<pubDate>Sun, 07 Mar 2010 12:21:41 +0000</pubDate>
		<dc:creator>Guillaume Plessis</dc:creator>
				<category><![CDATA[PHP]]></category>
		<category><![CDATA[PHP5]]></category>
		<category><![CDATA[release]]></category>

		<guid isPermaLink="false">http://www.dotdeb.org/?p=336</guid>
		<description><![CDATA[A few days ago, the PHP Group released PHP 5.2.13. It f [...]]]></description>
			<content:encoded><![CDATA[<p>A few days ago, the PHP Group released PHP 5.2.13. It fixes severe security issues and some other bugs :</p>
<blockquote><p>The PHP development team would like to announce the immediate availability of PHP 5.2.13. This release focuses on improving the stability of the PHP 5.2.x branch with over 40 bug fixes, some of which are security related. All users of PHP 5.2 are encouraged to upgrade to this release.</p>
<p><strong>Security Enhancements and Fixes in PHP 5.2.13:</strong></p>
<ul>
<li>Fixed safe_mode validation inside tempnam() when the directory path does not end with a /). (Martin Jansen)</li>
<li>Fixed a possible open_basedir/safe_mode bypass in the session extension identified by Grzegorz Stachowiak. (Ilia)</li>
<li>Improved LCG entropy. (Rasmus, Samy Kamkar)</li>
</ul>
<p>(&#8230;)</p></blockquote>
<p>On the Dotdeb side</p>
<ul>
<li>geoip, id3 and mailparse PECL extensions have been removed from the repository. If some of them were useful to you, please let me know. Don&#8217;t forget that there&#8221;s an easy way to <a title="How to package PECL extensions by yourself" href="http://www.dotdeb.org/2008/09/25/how-to-package-php-extensions-by-yourself/">package PECL extensions by yourself</a></li>
<li><a title="How to package PECL extensions by yourself" href="http://www.dotdeb.org/2008/09/25/how-to-package-php-extensions-by-yourself/"></a>the memcache extension has been downgraded to v3.0.3 because of a <a title="PECL bug #16061" href="http://pecl.php.net/bugs/bug.php?id=16061">bug in the session redundancy</a>.</li>
</ul>
<p>As usual, please read <a title="PHP 5.2.13 release announcement" href="http://www.php.net/releases/5_2_13.php">the release announcement</a> and the full <a title="The PHP5 Changelog" href="http://www.php.net/ChangeLog-5.php#5.2.13">Changelog</a> before upgrading.</p>
<script type="text/javascript">
var flattr_wp_ver = '0.9.14';
var flattr_uid = '13101';
var flattr_url = 'http://www.dotdeb.org';
var flattr_lng = 'en_GB';
var flattr_cat = 'text';
var flattr_tag = 'blog,wordpress,rss,feed';
var flattr_btn = 'large';
var flattr_tle = 'Dotdeb';
var flattr_dsc = 'The repository for Debian-based LAMP servers';
</script>
<script src="https://api.flattr.com/js/0.5.0/load.js?mode=auto" type="text/javascript"></script> <p>Feel free to Flattr this post at <a href="http://flattr.com/" title="Flattr" target="_blank">flattr.com</a>, if you like it.</p> <p><a href="http://flattr.com/" title="Flattr" target="_blank"><img src="http://www.dotdeb.org/wp-content/plugins/flattrss/button-compact-static-100x17.png" alt="flattr this!"/></a></p><div style="float: right; margin-left: 10px;"><a href="http://twitter.com/share?url=http://www.dotdeb.org/2010/03/07/php-5-2-13-is-available/&via=dotdeb&text=PHP 5.2.13 is available&related=w_a_s_t_e:Dotdeb's maintainer&lang=en&count=horizontal" class="twitter-share-button">Tweet</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script></div><div style="float: right; margin-left: 10px;"><a href="http://twitter.com/share?url=http://www.dotdeb.org/2010/03/07/php-5-2-13-is-available/&via=dotdeb&text=PHP 5.2.13 is available&related=w_a_s_t_e:Dotdeb's maintainer&lang=en&count=horizontal" class="twitter-share-button">Tweet</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script></div>]]></content:encoded>
			<wfw:commentRss>http://www.dotdeb.org/2010/03/07/php-5-2-13-is-available/feed/</wfw:commentRss>
		<slash:comments>25</slash:comments>
		</item>
		<item>
		<title>PHP 5.2.12 packages are here!</title>
		<link>http://www.dotdeb.org/2010/01/11/php-5-2-12-packages-are-here/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=php-5-2-12-packages-are-here</link>
		<comments>http://www.dotdeb.org/2010/01/11/php-5-2-12-packages-are-here/#comments</comments>
		<pubDate>Mon, 11 Jan 2010 21:49:56 +0000</pubDate>
		<dc:creator>Guillaume Plessis</dc:creator>
				<category><![CDATA[PHP]]></category>
		<category><![CDATA[PHP5]]></category>
		<category><![CDATA[release]]></category>

		<guid isPermaLink="false">http://www.dotdeb.org/?p=310</guid>
		<description><![CDATA[On December 17th 2009, the PHP Group released PHP 5.2.1 [...]]]></description>
			<content:encoded><![CDATA[<p>On December 17th 2009, the PHP Group released PHP 5.2.12 :</p>
<blockquote><p>The PHP development team would like to announce the immediate availability of PHP 5.2.12. This release focuses on improving the stability of the PHP 5.2.x branch with over 60 bug fixes, some of which are security related. All users of PHP 5.2 are encouraged to upgrade to this release.</p>
<p><strong>Security Enhancements and Fixes in PHP 5.2.12:</strong></p>
<ul>
<li>Fixed a safe_mode bypass in tempnam() identified by Grzegorz Stachowiak. (CVE-2009-3557, Rasmus)</li>
<li>Fixed a open_basedir bypass in posix_mkfifo() identified by Grzegorz Stachowiak. (CVE-2009-3558, Rasmus)</li>
<li>Added &#8220;max_file_uploads&#8221; INI directive, which can be set to limit the number of file uploads per-request to 20 by default, to prevent possible DOS via temporary file exhaustion, identified by Bogdan Calin. (CVE-2009-4017, Ilia)</li>
<li>Added protection for $_SESSION from interrupt corruption and improved &#8220;session.save_path&#8221; check, identified by Stefan Esser. (CVE-2009-4143, Stas)</li>
<li>Fixed bug #49785 (insufficient input string validation of htmlspecialchars()). (CVE-2009-4142, Moriyoshi, hello at iwamot dot com)</li>
</ul>
</blockquote>
<p>(Please read <a title="PHP 5.2.12 full announcement" href="http://www.php.net/releases/5_2_12.php">the full announcement</a> for more details)</p>
<p>Dotdeb packages of PHP 5.2.12 are now (finally) available for Debian &#8220;Lenny&#8221; and &#8220;Etch&#8221;, amd64 and i386.</p>
<p>Upgrading your servers is strongly encouraged because of several security issue, especially a <a title="multipart/form-data DoS" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4017">multipart/form-data DoS (CVE-2009-4017)</a>. Please set the <a title="the max_file_uploads parameter documentation" href="http://fr.php.net/manual/en/ini.core.php#ini.max-file-uploads">max_file_uploads</a> parameter carefully.</p>
 <p>Feel free to Flattr this post at <a href="http://flattr.com/" title="Flattr" target="_blank">flattr.com</a>, if you like it.</p> <p><a href="http://flattr.com/" title="Flattr" target="_blank"><img src="http://www.dotdeb.org/wp-content/plugins/flattrss/button-compact-static-100x17.png" alt="flattr this!"/></a></p><div style="float: right; margin-left: 10px;"><a href="http://twitter.com/share?url=http://www.dotdeb.org/2010/01/11/php-5-2-12-packages-are-here/&via=dotdeb&text=PHP 5.2.12 packages are here!&related=w_a_s_t_e:Dotdeb's maintainer&lang=en&count=horizontal" class="twitter-share-button">Tweet</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script></div><div style="float: right; margin-left: 10px;"><a href="http://twitter.com/share?url=http://www.dotdeb.org/2010/01/11/php-5-2-12-packages-are-here/&via=dotdeb&text=PHP 5.2.12 packages are here!&related=w_a_s_t_e:Dotdeb's maintainer&lang=en&count=horizontal" class="twitter-share-button">Tweet</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script></div>]]></content:encoded>
			<wfw:commentRss>http://www.dotdeb.org/2010/01/11/php-5-2-12-packages-are-here/feed/</wfw:commentRss>
		<slash:comments>18</slash:comments>
		</item>
		<item>
		<title>The PHP 5.3.1 packages have been updated</title>
		<link>http://www.dotdeb.org/2009/12/06/the-php-5-3-1-packages-have-been-updated/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=the-php-5-3-1-packages-have-been-updated</link>
		<comments>http://www.dotdeb.org/2009/12/06/the-php-5-3-1-packages-have-been-updated/#comments</comments>
		<pubDate>Sun, 06 Dec 2009 10:14:09 +0000</pubDate>
		<dc:creator>Guillaume Plessis</dc:creator>
				<category><![CDATA[PHP]]></category>
		<category><![CDATA[PHP5]]></category>
		<category><![CDATA[release]]></category>

		<guid isPermaLink="false">http://www.dotdeb.org/?p=304</guid>
		<description><![CDATA[The PHP 5.3.1 packages for Debian "Lenny" have been upd [...]]]></description>
			<content:encoded><![CDATA[<p>The PHP 5.3.1 packages for Debian &#8220;Lenny&#8221; have been updated to fix :</p>
<ul>
<li>the php5-fpm binary</li>
<li>the /etc/init.d/php5-fpm script</li>
</ul>
<p>All should work fine now.</p>
<script type="text/javascript">
var flattr_wp_ver = '0.9.14';
var flattr_uid = '13101';
var flattr_url = 'http://www.dotdeb.org';
var flattr_lng = 'en_GB';
var flattr_cat = 'text';
var flattr_tag = 'blog,wordpress,rss,feed';
var flattr_btn = 'large';
var flattr_tle = 'Dotdeb';
var flattr_dsc = 'The repository for Debian-based LAMP servers';
</script>
<script src="https://api.flattr.com/js/0.5.0/load.js?mode=auto" type="text/javascript"></script> <p>Feel free to Flattr this post at <a href="http://flattr.com/" title="Flattr" target="_blank">flattr.com</a>, if you like it.</p> <p><a href="http://flattr.com/" title="Flattr" target="_blank"><img src="http://www.dotdeb.org/wp-content/plugins/flattrss/button-compact-static-100x17.png" alt="flattr this!"/></a></p><div style="float: right; margin-left: 10px;"><a href="http://twitter.com/share?url=http://www.dotdeb.org/2009/12/06/the-php-5-3-1-packages-have-been-updated/&via=dotdeb&text=The PHP 5.3.1 packages have been updated&related=w_a_s_t_e:Dotdeb's maintainer&lang=en&count=horizontal" class="twitter-share-button">Tweet</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script></div><div style="float: right; margin-left: 10px;"><a href="http://twitter.com/share?url=http://www.dotdeb.org/2009/12/06/the-php-5-3-1-packages-have-been-updated/&via=dotdeb&text=The PHP 5.3.1 packages have been updated&related=w_a_s_t_e:Dotdeb's maintainer&lang=en&count=horizontal" class="twitter-share-button">Tweet</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script></div>]]></content:encoded>
			<wfw:commentRss>http://www.dotdeb.org/2009/12/06/the-php-5-3-1-packages-have-been-updated/feed/</wfw:commentRss>
		<slash:comments>27</slash:comments>
		</item>
		<item>
		<title>PHP 5.3.1 packages for Debian &#8220;Lenny&#8221; : they&#8217;re here!</title>
		<link>http://www.dotdeb.org/2009/11/30/php-5-3-1-packages-for-debian-lenny-theyre-here/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=php-5-3-1-packages-for-debian-lenny-theyre-here</link>
		<comments>http://www.dotdeb.org/2009/11/30/php-5-3-1-packages-for-debian-lenny-theyre-here/#comments</comments>
		<pubDate>Mon, 30 Nov 2009 08:58:33 +0000</pubDate>
		<dc:creator>Guillaume Plessis</dc:creator>
				<category><![CDATA[PHP]]></category>
		<category><![CDATA[PHP5]]></category>
		<category><![CDATA[release]]></category>

		<guid isPermaLink="false">http://www.dotdeb.org/?p=300</guid>
		<description><![CDATA[The official announcement
A few days ago, the PHP Grou [...]]]></description>
			<content:encoded><![CDATA[<h3>The official announcement</h3>
<p>A few days ago, the PHP Group released PHP 5.3.1 :</p>
<blockquote><p>The PHP development team would like to announce the immediate availability of PHP 5.3.1. This release focuses on improving the stability of the PHP 5.3.x branch with over 100 bug fixes, some of which are security related. All users of PHP are encouraged to upgrade to this release.</p>
<p><strong>Security Enhancements and Fixes in PHP 5.3.1:</strong></p>
<ul>
<li>Added &#8220;max_file_uploads&#8221; INI directive, which can be set to limit the number of file uploads per-request to 20 by default, to prevent possible DOS via temporary file exhaustion.</li>
<li>Added missing sanity checks around exif processing.</li>
<li>Fixed a safe_mode bypass in tempnam().</li>
<li>Fixed a open_basedir bypass in posix_mkfifo().</li>
<li>Fixed failing safe_mode_include_dir.</li>
</ul>
<p>Further details about the PHP 5.3.1 release can be found in the <a href="http://www.php.net/releases/5_3_1.php">release announcement</a>, and the full list of changes are available in the <a href="http://www.php.net/ChangeLog-5.php#5.3.1">ChangeLog</a>.</p></blockquote>
<p style="text-align: center;"><a title="SpeedHog by rdohms, on Flickr" href="http://www.flickr.com/photos/rdohms/4103030160/"><img class="aligncenter" src="http://farm3.static.flickr.com/2735/4103030160_e28bc28a93.jpg" alt="SpeedHog" width="500" height="375" /></a></p>
<h3>The Dotdeb changes</h3>
<p>On the Debian side, some changes were made :</p>
<ul>
<li>the packages are now patched with the official <a title="the Suhosin project" href="http://www.suhosin.org/">Suhosin</a> patch.</li>
<li>beside the apache2, apache2filter, CGI and CLI flavours, the <a title="the PHP-FPM project" href="http://php-fpm.org/about/">FPM</a> one has now its own dedicated package, named &#8220;php5-fpm&#8221;. It will allow you to have greater performances and a lot of more features on a CGI-style installation (FYI, an init script, a config file and a nginx config sample are provided).</li>
</ul>
<h3 style="font-size: 16px; font-weight: 700; padding: 0px; margin: 0px;">How to install?</h3>
<p>Because <a title="The official PHP documentation about migrating from PHP 5.2 to PHP 5.3" href="http://www.php.net/manual/migration53.php">migrating from PHP 5.2. to PHP 5.3</a> can break some applications, here is the Dotdeb release policy :</p>
<ul>
<li>PHP 5.2 is still the default branch for Debian Lenny for some weeks/months. PHP 5.3 packages are kept on a separate repository.</li>
<li>PHP 5.3 will be the default branch for the upcoming Debian Squeeze (mid-2010)</li>
</ul>
<p>Then , to install PHP 5.3 on your Debian &#8220;Lenny&#8221; box, just add these two entries in your <em>/etc/apt/sources.list</em> :</p>
<pre>deb http://php53.dotdeb.org stable all
deb-src http://php53.dotdeb.org stable all</pre>
<p>Now launch your favorite commands (<tt>apt-get update &amp;&amp; apt-get upgrade</tt>) to upgrade your box.</p>
<p>In case you enjoy this new release, feel free to <a title="Make a Dotdeb donation" href="https://www.paypal.com/xclick/business=gui%40moolfreet.com&amp;item_name=Dotdeb+Donation&amp;no_shipping=1&amp;no_note=1&amp;tax=0&amp;currency_code=EUR&amp;lc=us">donate</a> or to take a look at <a title="my Amazon.fr whishlist" href="http://www.amazon.fr/exec/obidos/registry/1OSKRT7G1UAPW/ref%3Dwl%5Fs%5F3/402-0961397-1287315">my whishlist</a>&#8230; Xmas is coming <img src='http://www.dotdeb.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
 <p>Feel free to Flattr this post at <a href="http://flattr.com/" title="Flattr" target="_blank">flattr.com</a>, if you like it.</p> <p><a href="http://flattr.com/" title="Flattr" target="_blank"><img src="http://www.dotdeb.org/wp-content/plugins/flattrss/button-compact-static-100x17.png" alt="flattr this!"/></a></p><div style="float: right; margin-left: 10px;"><a href="http://twitter.com/share?url=http://www.dotdeb.org/2009/11/30/php-5-3-1-packages-for-debian-lenny-theyre-here/&via=dotdeb&text=PHP 5.3.1 packages for Debian "Lenny" : they're here!&related=w_a_s_t_e:Dotdeb's maintainer&lang=en&count=horizontal" class="twitter-share-button">Tweet</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script></div><div style="float: right; margin-left: 10px;"><a href="http://twitter.com/share?url=http://www.dotdeb.org/2009/11/30/php-5-3-1-packages-for-debian-lenny-theyre-here/&via=dotdeb&text=PHP 5.3.1 packages for Debian "Lenny" : they're here!&related=w_a_s_t_e:Dotdeb's maintainer&lang=en&count=horizontal" class="twitter-share-button">Tweet</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script></div>]]></content:encoded>
			<wfw:commentRss>http://www.dotdeb.org/2009/11/30/php-5-3-1-packages-for-debian-lenny-theyre-here/feed/</wfw:commentRss>
		<slash:comments>73</slash:comments>
		</item>
		<item>
		<title>PHP 5.2.11 packages are available for Etch and Lenny</title>
		<link>http://www.dotdeb.org/2009/09/23/php-5-2-11-packages-are-available-for-etch-and-lenny/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=php-5-2-11-packages-are-available-for-etch-and-lenny</link>
		<comments>http://www.dotdeb.org/2009/09/23/php-5-2-11-packages-are-available-for-etch-and-lenny/#comments</comments>
		<pubDate>Wed, 23 Sep 2009 15:17:42 +0000</pubDate>
		<dc:creator>Guillaume Plessis</dc:creator>
				<category><![CDATA[PHP]]></category>
		<category><![CDATA[PHP5]]></category>
		<category><![CDATA[release]]></category>

		<guid isPermaLink="false">http://www.dotdeb.org/?p=272</guid>
		<description><![CDATA[PHP 5.2.11 has been published a few days ago by the PHP [...]]]></description>
			<content:encoded><![CDATA[<p>PHP 5.2.11 has been <a title="PHP 5.2.11 release announcement" href="http://www.php.net/releases/5_2_11.php">published</a> a few days ago by the PHP Group and its packages are now available for Debian Etch and Lenny, amd64 and i386. It fixes a lot of bugs and some security issues :</p>
<ul>
<li>Fixed certificate validation inside php_openssl_apply_verification_policy. (Ryan Sleevi, Ilia)</li>
<li>Fixed sanity check for the color index in imagecolortransparent(). (Pierre)</li>
<li>Added missing sanity checks around exif processing. (Ilia)</li>
<li>Fixed bug #44683 (popen crashes when an invalid mode is passed). (Pierre)</li>
</ul>
<p>To avoid the same <a title="PHP 5.2.10 negative feedbacks" href="http://www.dotdeb.org/2009/06/25/php-5-2-10-packages-for-lennyetch-are-now-available/#comments">negative feedbacks</a> as about PHP 5.2.10, a lot of debug and changes has been made :</p>
<ul>
<li>The <tt>embedded_timezone</tt> patch has been disabled. You now have to set <tt><a href="http://www.php.net/manual/en/datetime.configuration.php#ini.date.timezone">date.timezone</a></tt> manually in your <tt>/etc/php5/*/php.ini</tt> files, depending on your machine.</li>
</ul>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-275" title="date.timezone" src="http://www.dotdeb.org/wp-content/uploads/2009/09/date.timezone.png" alt="date.timezone" width="388" height="198" /></p>
<ul>
<li>If you encounter problems with some applications and the CGI flavour, remember to set <tt><a href="http://www.php.net/manual/en/ini.core.php#ini.cgi.fix-pathinfo">cgi.fix_pathinfo</a>=1</tt> in your <tt>php.ini</tt> (thanks Scott for <a title="Pathinfo fix for the CGI flavour of PHP5" href="http://www.dotdeb.org/2009/06/25/php-5-2-10-packages-for-lennyetch-are-now-available/comment-page-2/#comment-1336">reporting this</a>)</li>
</ul>
<p>As usual, read the full <a title="PHP 5.2.11 full Changelog" href="http://www.php.net/ChangeLog-5.php#5.2.11">Changelog</a> before upgrading.</p>
<script type="text/javascript">
var flattr_wp_ver = '0.9.14';
var flattr_uid = '13101';
var flattr_url = 'http://www.dotdeb.org';
var flattr_lng = 'en_GB';
var flattr_cat = 'text';
var flattr_tag = 'blog,wordpress,rss,feed';
var flattr_btn = 'large';
var flattr_tle = 'Dotdeb';
var flattr_dsc = 'The repository for Debian-based LAMP servers';
</script>
<script src="https://api.flattr.com/js/0.5.0/load.js?mode=auto" type="text/javascript"></script> <p>Feel free to Flattr this post at <a href="http://flattr.com/" title="Flattr" target="_blank">flattr.com</a>, if you like it.</p> <p><a href="http://flattr.com/" title="Flattr" target="_blank"><img src="http://www.dotdeb.org/wp-content/plugins/flattrss/button-compact-static-100x17.png" alt="flattr this!"/></a></p><div style="float: right; margin-left: 10px;"><a href="http://twitter.com/share?url=http://www.dotdeb.org/2009/09/23/php-5-2-11-packages-are-available-for-etch-and-lenny/&via=dotdeb&text=PHP 5.2.11 packages are available for Etch and Lenny&related=w_a_s_t_e:Dotdeb's maintainer&lang=en&count=horizontal" class="twitter-share-button">Tweet</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script></div><div style="float: right; margin-left: 10px;"><a href="http://twitter.com/share?url=http://www.dotdeb.org/2009/09/23/php-5-2-11-packages-are-available-for-etch-and-lenny/&via=dotdeb&text=PHP 5.2.11 packages are available for Etch and Lenny&related=w_a_s_t_e:Dotdeb's maintainer&lang=en&count=horizontal" class="twitter-share-button">Tweet</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script></div>]]></content:encoded>
			<wfw:commentRss>http://www.dotdeb.org/2009/09/23/php-5-2-11-packages-are-available-for-etch-and-lenny/feed/</wfw:commentRss>
		<slash:comments>30</slash:comments>
		</item>
	</channel>
</rss>
